Alexander Heldt cffaec5fe8 manatee: add self-hosted todo app
Wire the offline-first todo app (github: local /home/alex/code/todo) into
manatee, following the app-module convention:

- flake input `todo` (local git checkout for now; gitea URL commented) with
  nixpkgs following.
- hosts/manatee/modules/todo: mod.todo option importing the app's NixOS module;
  runs on 127.0.0.1:8091, secureCookies, token from agenix; the host owns the
  nginx vhost (todo.ppp.pm, forceSSL + useACMEHost) and homepage card.
- mod.todo.enable = true.
- certs: todo.ppp.pm DNS-01 cert via hetzner.
- home-assistant DNS updater: add `todo` to the Hetzner subdomain list.
- secrets: todo-token.age (encrypted access token) + recipients in secrets.nix.
2026-08-13 12:36:18 +00:00
2026-08-13 12:36:18 +00:00
2026-08-13 12:36:18 +00:00
2025-07-10 16:21:03 +02:00
2024-09-02 21:07:34 +02:00
2024-09-02 21:07:34 +02:00
2026-08-13 12:36:18 +00:00
2026-08-13 12:36:18 +00:00

config-manager

./config-manager is a module that contains a script to make usage of this flake easier.

To install it

  1. first add the module to the nixOS system connfiguration
  2. set config-manager.flakePath = <path to this flake>
  3. run nixos-rebuild switch --flake .#<configuration> after that cm will be available on $PATH.

Secrets

Secrets are managed by agenix (https://github.com/ryantm/agenix).

Creating new secrets

  1. Update secrets/secrets.nix with the new secret.

  2. When inside ./secrets:

EDITOR=vim agenix -e "some-secret.age"

This will create a new secret. To view its content one can do:

EDITOR=vim agenix -d "some-secret.age" -i ~/.ssh/alex.pinwheel

Or use some other SSH key that is has been used to key the secret.

Test VM

Build the test VM with the command:

cm  --build-test-vm

and test it with:

cm  --run-test-vm
S
Description
No description provided
Readme
1.6 MiB
Languages
Nix 76.4%
HTML 20.1%
Shell 3.5%